Remix.run Logo
davidfischer 9 hours ago

Here's my take:

* JA3s are mostly useless. JA4s supersede them entirely.

* Using JA4s in rate limits is pretty useful and helps a lot against proxy scraping. It was not very helpful in this attack.

* Bot detections are somewhat helpful but they don't solve scrapers/attacks by themselves. They're useful as a 2nd/3rd data point (eg. low bot score + bot detection + something else)

cute_boi 7 hours ago | parent [-]

isn't JA4 also useless because it is so easy to spoof tls. For eg. cycletls for nodejs etc..

davidfischer 7 hours ago | parent [-]

It will probably be useless one day. In practice, it is still useful today though not for this attack.

johneth 7 hours ago | parent [-]

There's also the JA4+ suite (https://github.com/FoxIO-LLC/ja4), in addition to standard JA4.